7.8

CVE-2019-18619

Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SynapticsVfs75xx Firmware Version5.2.225.26
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.2.318.26
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.2.524.26
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.2.3530.26
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.3.3539.26
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.3.1116
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.8.1096
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.10.1093
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.11.1106
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.15.1102
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.38.1058
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.2734.1050
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.5.2811.1050
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version5.6.23.1000
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version6.0.14.1108
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version6.0.32.1104
   SynapticsVfs75xx Version-
SynapticsVfs75xx Firmware Version6.0.42.1107
   SynapticsVfs75xx Version-
LenovoThinkpad 25 Firmware Version < 5.2.3540.26
   LenovoThinkpad 25 Version-
LenovoThankpad A475 Firmware Version < 5.02.3539.0026
   LenovoThankpad A475 Version-
LenovoThankpad A485 Firmware Version < 5.03.3542.0026
   LenovoThankpad A485 Version-
LenovoThinkpad E480 Firmware Version < 5.2.321.26
   LenovoThinkpad E480 Version-
LenovoThinkpad E580 Firmware Version < 5.2.321.26
   LenovoThinkpad E580 Version-
LenovoThinkpad E485 Firmware Version < 5.2.321.26
   LenovoThinkpad E485 Version-
LenovoThinkpad E585 Firmware Version < 5.2.321.26
   LenovoThinkpad E585 Version-
LenovoThinkpad E490s Firmware Version < 5.2.321.26
   LenovoThinkpad E490s Version-
LenovoThinkpad S3 Firmware Version < 5.2.321.26
   LenovoThinkpad S3 Version-
LenovoThinkpad E490 Firmware Version < 5.2.321.26
   LenovoThinkpad E490 Version-
LenovoThinkpad E590 Firmware Version < 5.2.321.26
   LenovoThinkpad E590 Version-
LenovoThinkpad R490 Firmware Version < 5.2.321.26
   LenovoThinkpad R490 Version-
LenovoThinkpad R590 Firmware Version < 5.2.321.26
   LenovoThinkpad R590 Version-
LenovoThinkpad L480 Firmware Version < 5.3.3542.26
   LenovoThinkpad L480 Version-
LenovoThinkpad L580 Firmware Version < 5.3.3542.26
   LenovoThinkpad L580 Version-
LenovoThinkpad P1 Firmware Version < 5.3.3542.26
   LenovoThinkpad P1 Version-
LenovoThinkpad P1 Gen 2 Firmware Version < 6.0.36.1105
   LenovoThinkpad P1 Gen 2 Version-
LenovoThinkpad X1 Extreme 2nd Firmware Version < 6.0.36.1105
   LenovoThinkpad X1 Extreme 2nd Version-
LenovoThinkpad P43s Firmware Version < 6.0.36.1105
   LenovoThinkpad P43s Version-
LenovoThinkpad P50 Firmware Version < 5.1.338.26
   LenovoThinkpad P50 Version-
LenovoThinkpad P51 Firmware Version < 5.2.3540.26
   LenovoThinkpad P51 Version-
LenovoThinkpad P51s (20jx) Firmware Version < 5.2.3540.26
   LenovoThinkpad P51s (20jx) Version-
LenovoThinkpad P51s (20kx) Firmware Version < 5.2.3540.26
   LenovoThinkpad P51s (20kx) Version-
LenovoThinkpad P51s (20hx) Firmware Version < 5.2.3540.26
   LenovoThinkpad P51s (20hx) Version-
LenovoThinkpad P52 Firmware Version < 5.2.3540.26
   LenovoThinkpad P52 Version-
LenovoThinkpad P52s Firmware Version < 5.3.3542.26
   LenovoThinkpad P52s Version-
LenovoThinkpad P53 Firmware Version < 6.0.36.1105
   LenovoThinkpad P53 Version-
LenovoThinkpad P53s Firmware Version < 6.0.36.1105
   LenovoThinkpad P53s Version-
LenovoThinkpad P70 Firmware Version < 5.1.338.26
   LenovoThinkpad P70 Version-
LenovoThinkpad P71 (20hx) Firmware Version < 5.2.3540.26
   LenovoThinkpad P71 (20hx) Version-
LenovoThinkpad P72 Firmware Version < 5.3.3542.26
   LenovoThinkpad P72 Version-
LenovoThinkpad P73 Firmware Version < 5.3.3542.26
   LenovoThinkpad P73 Version-
LenovoThinkpad T25 (20k7) Firmware Version < 5.2.3540.26
   LenovoThinkpad T25 (20k7) Version-
LenovoThinkpad T460p Firmware Version < 5.1.338.26
   LenovoThinkpad T460p Version-
LenovoThinkpad T460s Firmware Version < 5.1.338.26
   LenovoThinkpad T460s Version-
LenovoThinkpad T470 (20hx) Firmware Version < 5.2.3540.26
   LenovoThinkpad T470 (20hx) Version-
LenovoThinkpad T470 (20jx) Firmware Version < 5.2.3540.26
   LenovoThinkpad T470 (20jx) Version-
LenovoThinkpad T470p Firmware Version < 5.2.3540.26
   LenovoThinkpad T470p Version-
LenovoThinkpad T470s (20hx) Firmware Version < 5.2.3540.26
   LenovoThinkpad T470s (20hx) Version-
LenovoThinkpad T470s (20jx) Firmware Version < 5.2.3540.26
   LenovoThinkpad T470s (20jx) Version-
LenovoThinkpad T480 Firmware Version < 5.3.3542.26
   LenovoThinkpad T480 Version-
LenovoThinkpad T480s Firmware Version < 5.3.3542.26
   LenovoThinkpad T480s Version-
LenovoThinkpad T490 Firmware Version < 6.0.36.1105
   LenovoThinkpad T490 Version-
LenovoThinkpad T490s Firmware Version < 6.0.36.1105
   LenovoThinkpad T490s Version-
LenovoThinkpad T570 (20hx) Firmware Version < 5.2.3540.26
   LenovoThinkpad T570 (20hx) Version-
LenovoThinkpad T570(20jx) Firmware Version < 5.2.3540.26
   LenovoThinkpad T570(20jx) Version-
LenovoThinkpad T580 Firmware Version < 5.3.3542.26
   LenovoThinkpad T580 Version-
LenovoThinkpad T590 Firmware Version < 6.0.36.1105
   LenovoThinkpad T590 Version-
LenovoThinkpad X1 Carbon (20hx) Firmware Version < 5.2.3540.26
   LenovoThinkpad X1 Carbon (20hx) Version-
LenovoThinkpad X1 Carbon (20kx) Firmware Version < 5.3.3542.26
   LenovoThinkpad X1 Carbon (20kx) Version-
LenovoThinkpad X1 Carbon Firmware Version < 5.1.338.26
   LenovoThinkpad X1 Carbon Version-
LenovoThinkpad X1 Yoga 4th Gen Firmware Version < 5.1.338.26
   LenovoThinkpad X1 Yoga 4th Gen Version-
LenovoThinkpad X1 Extreme Firmware Version < 5.3.3542.26
   LenovoThinkpad X1 Extreme Version-
LenovoThinkpad X1 Tablet Firmware Version < 5.5.40.1058
   LenovoThinkpad X1 Tablet Version-
LenovoThinkpad X1 Tablet (20jx) Firmware Version < 5.2.227.26
   LenovoThinkpad X1 Tablet (20jx) Version-
LenovoThinkpad X1 Yoga Firmware Version < 5.1.338.26
   LenovoThinkpad X1 Yoga Version-
LenovoThinkpad X1 Yoga (20jx) Firmware Version < 5.2.3540.26
   LenovoThinkpad X1 Yoga (20jx) Version-
LenovoThinkpad X1 Yoga 3rd Gen Firmware Version < 5.3.3542.26
   LenovoThinkpad X1 Yoga 3rd Gen Version-
LenovoThinkpad X270 Firmware Version < 5.2.3540.26
   LenovoThinkpad X270 Version-
LenovoThinkpad X280 Firmware Version < 5.3.3542.26
   LenovoThinkpad X280 Version-
LenovoThinkpad X380 Yoga Firmware Version < 5.3.3542.26
   LenovoThinkpad X380 Yoga Version-
LenovoThinkpad X390 Firmware Version < 6.0.36.1105
   LenovoThinkpad X390 Version-
LenovoThinkpad X390 Yoga Firmware Version < 6.0.36.1105
   LenovoThinkpad X390 Yoga Version-
LenovoThinkpad Yoga 370 Firmware Version < 5.2.3540.26
   LenovoThinkpad Yoga 370 Version-
LenovoThinkpad S1 3rd Firmware Version < 5.2.3540.26
   LenovoThinkpad S1 3rd Version-
LenovoThinkpad Yoga 260 Firmware Version < 5.1.338.26
   LenovoThinkpad Yoga 260 Version-
LenovoThinkpad Yoga S1 Firmware Version < 5.1.338.26
   LenovoThinkpad Yoga S1 Version-
LenovoThinkpad A275 Firmware Version < 5.2.3535.26
   LenovoThinkpad A275 Version-
HpEnvy - 13t-ah100 Firmware Version < 5.5.11.1093
   HpEnvy - 13t-ah100 Version-
HpEnvy - 13t-aq100 Firmware Version < 6.0.39.1111
   HpEnvy - 13t-aq100 Version-
HpEnvy 13-ah0xxx Firmware Version < 5.5.11.1093
   HpEnvy 13-ah0xxx Version-
HpEnvy 13-ah1xxx Firmware Version < 5.5.11.1093
   HpEnvy 13-ah1xxx Version-
HpEnvy 13-aq0xxx Firmware Version < 6.0.39.1111
   HpEnvy 13-aq0xxx Version-
HpEnvy 13-aq1xxx Firmware Version < 6.0.39.1111
   HpEnvy 13-aq1xxx Version-
HpEnvy - 17t-bw000 Firmware Version < 5.5.11.1093
   HpEnvy - 17t-bw000 Version-
HpEnvy - 17t-ce000 Firmware Version < 6.0.39.1111
   HpEnvy - 17t-ce000 Version-
HpEnvy - 17t-ce100 Firmware Version < 6.0.39.1111
   HpEnvy - 17t-ce100 Version-
HpEnvy 17-bw0xxx Firmware Version < 5.5.11.1093
   HpEnvy 17-bw0xxx Version-
HpEnvy 17-ce0xxx Firmware Version < 6.0.39.1111
   HpEnvy 17-ce0xxx Version-
HpEnvy 17-ce1xxx Firmware Version < 6.0.39.1111
   HpEnvy 17-ce1xxx Version-
HpEnvy 17m-bw0xxx Firmware Version < 5.5.11.1093
   HpEnvy 17m-bw0xxx Version-
HpEnvy 17m-ce0xxx Firmware Version < 6.0.39.1111
   HpEnvy 17m-ce0xxx Version-
HpEnvy 17m-ce1xxx Firmware Version < 6.0.39.1111
   HpEnvy 17m-ce1xxx Version-
HpEnvy X360 - 15t-cn000 Firmware Version < 5.5.11.1093
   HpEnvy X360 - 15t-cn000 Version-
HpEnvy X360 - 15t-dr000 Firmware Version < 6.0.39.1111
   HpEnvy X360 - 15t-dr000 Version-
HpEnvy X360 - 15t-dr100 Firmware Version < 6.0.39.1111
   HpEnvy X360 - 15t-dr100 Version-
HpEnvy 15-cn0xxx X360 Firmware Version < 5.5.11.1093
   HpEnvy 15-cn0xxx X360 Version-
HpEnvy 15-cn1xxx X360 Firmware Version < 5.5.11.1093
   HpEnvy 15-cn1xxx X360 Version-
HpEnvy 15-dr0xxx X360 Firmware Version < 6.0.39.1111
   HpEnvy 15-dr0xxx X360 Version-
HpEnvy 15-dr1xxx X360 Firmware Version < 6.0.39.1111
   HpEnvy 15-dr1xxx X360 Version-
HpEnvy 15m-cn0xxx X360 Firmware Version < 5.5.11.1093
   HpEnvy 15m-cn0xxx X360 Version-
HpEnvy 15m-dr0xxx X360 Firmware Version < 6.0.39.1111
   HpEnvy 15m-dr0xxx X360 Version-
HpEnvy 15m-dr1xxx X360 Firmware Version < 6.0.39.1111
   HpEnvy 15m-dr1xxx X360 Version-
HpPavilion X360 - 14t-cd000 Firmware Version < 5.5.11.1093
   HpPavilion X360 - 14t-cd000 Version-
HpPavilion X360 - 15t-dq000 Firmware Version < 5.5.8.1116
   HpPavilion X360 - 15t-dq000 Version-
HpPavilion X360 - 15t-dq100 Firmware Version < 5.5.8.1116
   HpPavilion X360 - 15t-dq100 Version-
HpPavilion X360 14t-cd100 Firmware Version < 5.5.11.1093
   HpPavilion X360 14t-cd100 Version-
HpPavilion X360 14t-dh000 Firmware Version < 5.5.8.1116
   HpPavilion X360 14t-dh000 Version-
HpPavilion 14-cd1xxx X360 Firmware Version < 5.5.11.1093
   HpPavilion 14-cd1xxx X360 Version-
HpPavilion 14-cd2xxx X360 Firmware Version < 5.5.11.1093
   HpPavilion 14-cd2xxx X360 Version-
HpPavilion 14-dh0xxx X360 Firmware Version < 5.5.8.1116
   HpPavilion 14-dh0xxx X360 Version-
HpPavilion 14m-cd0xxx X360 Firmware Version < 5.5.11.1093
   HpPavilion 14m-cd0xxx X360 Version-
HpPavilion 14m-dh0xxx X360 Firmware Version < 5.5.8.1116
   HpPavilion 14m-dh0xxx X360 Version-
HpPavilion 15 Firmware Version < 5.5.8.1116
   HpPavilion 15 Version-
HpSpectre X360 Firmware Version < 5.5.26.1102
   HpSpectre X360 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.343
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-763 Release of Invalid Pointer or Reference

The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.